top | item 46046636

Big attack on NPM – Shai-Hulud 2.0

2 points| thomasfl | 3 months ago |about.gitlab.com

3 comments

order

nycalexander|3 months ago

Made a package (that I needed personally), to easily reinstall all dependencies (using the same versions) in a project and check them using Aikido's safe chain for malware (supported npm, pnpm, bun, and yarn). It also easily switches a project's package manager to another. https://www.npmjs.com/package/eazypm

thomasfl|3 months ago

This is a nasty npm attack. It steals API keys and credits.